55 points luispa 1 day ago 23 comments

ltbarcly3 46 minutes ago | parent

> Two quick notes first. The impact I describe is hypothetical. It’s what an attacker could have done with this access, but luckily I found the bug instead, reported it, and never touched any customer data or PII.

I am the last person to judge someone for using AI to help them write a blog post, but what I wonder is: Do people not read what the AI produces before putting their name on it, or is the AI writing style not obvious to some people, or do they just not care that it's obviously AI and bad style?

t-writescode 40 minutes ago | parent

That.. looks like a normal sentence to me, and very probably one of the ones Microsoft required they add.

Did you give the article a once-over beyond that? It’s one of the decidedly not-AI lines.

ltbarcly3 38 minutes ago | parent

Prefixing saying something with "Two quick notes first" is extremely common AI meta commentary. You may be right that it is something Microsoft insisted he put at the top, which would also explain the weird style.

functionmouse 23 minutes ago | parent

From where do you think AI learned that?

Forgeties79 21 minutes ago | parent

All AI semantic tendencies were “learned” from us. That doesn’t change anything.

vonneumannstan 17 minutes ago | parent

Weird user preferences during RLHF. Also how we got bulleted lists and emojis everywhere.

0x_rs 18 minutes ago | parent

It's not a "normal" sentence and is quite clearly produced by an LLM, it's a typical Claudeism so probably that. The entire post is also flagged by Pangram, so OP is correct.

f311a 41 minutes ago | parent

What is Antares? Can't find anything related to it except for the 1B model, which does not seem to be capable of autoresearch.

UPD: It's his personal bot.

Alifatisk 5 minutes ago | parent

> I also started building AI into how I hunt, which led me to develop Antares, my personal AI hackbot.

sdfhbdf 23 minutes ago | parent

> awarded $5000

It's a little perplexing. Of course it's always a controversial topic since it's difficult to value an exploit, but whenever we read about these online, which probably goes through some survivorship bias, they seem pretty low.

On https://www.microsoft.com/en-us/msrc/bounty it seems the top is $100,000 or $250,000 depending which program this counts under.

What does HN think? Why would it be only $5000?

muglug 11 minutes ago | parent

As I understand it, bug bounty awards are a rough proxy for "would nation-state actors be able to exploit this for operational purposes without getting caught".

Zero-click iPhone exploits that affect the current OS and also previous ones are worth hundreds of thousands.

Kuyawa 20 minutes ago | parent

Next time you find a bug like that, offer it to the black market, you could make millions instead of measly salty peanuts

sdcfgy 12 minutes ago | parent

I bet someone already did that and didn't disclose it.

arm32 7 minutes ago | parent

Now some blackhat somewhere can't afford their monthly Lamborghini payment.

khalic 19 minutes ago | parent

You’re going places kid :) keep up the good work

matroxmemories 14 minutes ago | parent

Possibly jail if the wrong people get upset.

Waterluvian 8 minutes ago | parent

Great way to use up that 6-10 years of vacation and sabbatical time.

er0k 15 minutes ago | parent

wow I am so surprised to hear once again how JWTs are terrible

https://www.howmanydayssinceajwtalgnonevuln.com/

sdcfgy 13 minutes ago | parent

Wait until someone does that to your favourite cloud provider's customer data.